Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cato CTRL Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan

SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services.

The Hidden Cost of "Free": When Platform Incentives Become Lock-In

In enterprise software, “free” is rarely free. A free year can be a smart commercial incentive. It can also become a financial trap if the real cost, payment terms, and renewal baseline are unclear. When a platform deal looks almost too good to question, CFOs should question it first. Large multi-year incentives can look like a procurement win. They lower the apparent cost of entry, support a consolidation story, and create the impression of immediate savings.

How to Reduce Risk Without Shutting Down Operations

Discovering a vulnerable asset doesn't have to trigger panic. In this video, Daniel dos Santos explains how organizations can reduce risk while investigations are still underway by limiting reachability, tightening access controls, and using segmentation to restrict exposure—without disrupting critical business operations.

Total visibility, total control: Inside DDI Central's IP address management tower

Managing IP addresses across a growing network means tracking a lot of moving parts at once, including: sites, clusters, subnets, VLANs, leases, and DNS records. Add in subnets imported from other tools, addresses that were assigned manually years ago, and the occasional reservation nobody remembers creating, and it's easy for even a well-run network to lose a clear picture of what's actually happening across its address space.

Inside Locked Shields 2026: How network evidence helped defenders cut through live-fire chaos

Locked Shields 2026 brought together more than 4,000 participants from 41 nations for a live-fire cyber defense exercise built around the kind of pressure SecOps teams know well: Critical systems under attack, incomplete context, multiple tools, and no time to waste. For Corelight, the exercise reinforced a practical lesson: In high-pressure defense, network evidence is not just another data source.

Build the Zero-Day Playbook Before the Next Crisis

In this video, Daniel dos Santos, VP of Research, explains why organizations should establish a zero-day containment playbook before a crisis occurs. A well-defined playbook connects response actions to assets, critical services, and business functions while outlining decision-making, impact validation, and crisis communication processes. When a real-world zero-day strikes, there is no time to create a plan from scratch. Preparation helps teams respond faster, align stakeholders, and reduce uncertainty during high-pressure situations.

Exclusive Networks cooks up 'successful recipe' with One Identity

Just shy of starting three years ago, the One Identity x Exclusive Networks partnership is still going strong, and Matthew Paynter, vendor alliances director at Exclusive Networks, chalks it up to, among many things, the honest, realistic conversations and strong day-to-day working relationships One Identity has upheld since the beginning. Explore how this global cybersecurity distributor came to work with One Identity, what benefits have come of this alliance and where One Identity stands out among other vendor options.

Smarter Security with New Integrations from Cato Networks and CrowdStrike

Today, Cato Networks announced a collaboration with CrowdStrike to integrate the Cato SASE Platform with the CrowdStrike Falcon platform. Together, the companies are helping security teams unify network and endpoint visibility, streamline investigations, and accelerate threat detection and response. If there’s one frustration that unites IT and security professionals, it’s this: too many tools that don’t talk to each other.

How Firewall Rule Sprawl Puts Client Networks at Risk Over Time

A firewall rule that made sense two years ago rarely gets revisited once the project behind it wraps up. It sits in the config doing nothing, forgotten, until an audit or an incident force someone to ask why it's there. That's the mechanism behind firewall rule sprawl, and it's one of the more overlooked risks in managing client environments over time.